The FBI’s CJIS Security Policy has undergone significant changes in recent years, with the latest update, version 6.1, published in June 2026. This modernized policy is closely aligned with NIST SP 800-53 and addresses omissions, corrections, and additions highlighted throughout 2025. For security teams already working towards the requirements introduced in v6.0, the overall direction has not changed, but there are still updates that warrant attention.
One of the key changes between v6.0 and v6.1 concerns encryption. Under SC-13, which covers cryptographic protection for CJI in transit outside a physically secure location, v6.0 specified a symmetric cipher key of at least 128-bit strength. Version 6.1 raises that requirement to at least 256-bit strength. This change is significant because it strengthens the encryption requirements for sensitive information, making it more difficult for unauthorized parties to access it.
Another notable change is in vulnerability management. Under v6.0, CJIS required agencies to use vulnerability scanning tools at least quarterly to determine whether applicable security-related software and firmware updates had been installed, as well as following security incidents involving CJI. Version 6.1 changes that frequency from quarterly to at least monthly, requiring more frequent scans to stay ahead of potential vulnerabilities.
The audit requirements under CJIS v6.1 also warrant attention. While version 6.1 is now the current policy, agencies shouldn’t assume an immediate switch to a new audit baseline. The modernized policy uses priority levels and phased audit and sanction dates, with Priority 1 controls sanctionable since October 1, 2024. Priority 2, 3, and 4 controls are in “zero-cycle” status until September 30, 2027.
It’s essential for agencies to confirm the current audit expectations with their relevant State CJIS Systems Agency (CSA) while working towards the newer requirements. Waiting for a control to become sanctionable before addressing it can create unnecessary work later, particularly when audit programs themselves are moving toward more continuous assessment.
The latest CJIS Board meeting in October 2025 highlighted recurring issues in audits, including multi-factor authentication (MFA), new policies, BYOD policies and procedures, training, security agreements, event logging, and fingerprinting. The meeting also outlined a move away from relying primarily on triennial audit visits towards more continuous assessment.
One takeaway from this update is that compliance increasingly depends not only on having a control but on being able to demonstrate consistently that it is working. For agencies planning their CJIS work, it’s essential to focus on implementing controls and ensuring they are functioning correctly, rather than just meeting the minimum requirements.
As we continue to navigate the complex world of cybersecurity, it’s crucial for security teams to stay up-to-date with the latest policies and guidelines. The FBI’s CJIS Security Policy is a critical component of this effort, and understanding the changes in version 6.1 will help agencies ensure they are meeting the required standards and protecting sensitive information.
Source: Bleeping Computer — 2026-09-21